SAIC logo

Risk Management Framework Analyst

SAIC

Colorado Springs, COContract$80–120K/yrSeen 1w agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$80–120K/yr
Location
Colorado Springs, CO
Schedule
Contract
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

DoD Manual (DoDM) 8140.03 Intermediate Level Certification (e.g., CompTIA Security+)TS/SCI clearance

Job overview

SAIC is seeking a Risk Management Framework (RMF) Analyst for an ISSO position supporting RMF requirements of NORAD/USNORTHCOM IT Enterprise Services contract, working onsite in Colorado Springs. The role involves maintaining system registrations, security baselines, and evidentiary records, and ensuring continuous monitoring and authority to operate sustainment.

Skills & qualifications

RequiredNice to have

Skills

RMF ProcesseMASSACASSCAPSTIG ViewerAutomated Compliance ToolsChange Advisory Boards

Qualifications

DoD Manual (DoDM) 8140.03 Intermediate Level Certification (e.g., CompTIA Security+)Bachelor’s Degree in Information Assurance, Cybersecurity or Related FieldHigh School Diploma or Equivalent3–5 Years Relevant Experience7–10 Years Relevant ExperienceAt Least 2 Years Direct ISSO or Cybersecurity Practitioner Experience Supporting DoD SystemsDirect Experience Managing RMF Lifecycle Artifacts and eMASS Package ManagementProven Experience Authoring, Tracking, and Coordinating Technical Remediation of POA&MsActive Top Secret/Sensitive Compartmented Information (TS/SCI) Security ClearanceAbility to Work Effectively in Team-Focused Dynamic High-Tempo EnvironmentExperience Using STIG Viewer and Automated Compliance ToolsPrior Experience Participating in Change Advisory Boards (CABs)

Full job description

Description

SAIC is seeking a Risk Management Framework (RMF) Analyst for an Information Systems Security Officer (ISSO) position supporting the RMF requirements of the North American Aerospace Defense Command and United States Northern Command (NORAD/USNORTHCOM) Information Technology (IT) Enterprise Services (NITES) contract. The primary work location is onsite in Colorado Springs.

Responsibilities:

  • Supporting and executing the RMF process across multiple enterprise systems and enclaves by maintaining system registrations, security baselines, and evidentiary records within the Enterprise Mission Assurance Support Service (eMASS).

  • Operating with ISSO-level ownership to independently drive continuous monitoring and Authority to Operate (ATO) sustainment, ensuring an uninterrupted and robust security posture.

  • Ensuring cybersecurity standards and operational hygiene are consistently maintained to support a Cyber Operational Readiness Assessment (CORA)-ready posture.

  • Managing the continuous cybersecurity posture of enterprise systems and identifying mitigations necessary to meet Department of Defense Directive (DoDD) 8500.01, Department of Defense Instruction (DoDI) 8510.01, DoDD 8140.01, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 requirements.

  • Analyzing and correlating scan results from the Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), and other approved tools to evaluate system risk, determine security posture, and maintain ATO and Assess Only authorizations.

  • Assisting with system categorization in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, including confidentiality, integrity, and availability impact levels, as information types, mission profiles, and system interconnections evolve.

  • Leading the development, maintenance, and technical validation of System Security Plans (SSPs), ensuring evidentiary artifacts accurately reflect current technical architectures and that applicable Security Technical Implementation Guides (STIGs) are implemented.

  • Exercising end-to-end ownership of Plans of Action and Milestones (POA&Ms) by systematically evaluating deficiencies, determining risk impacts, and coordinating with technical stakeholders to drive findings to timely closure.

  • Collaborating proactively with system administrators, network engineers, and leadership to remediate STIG findings, vulnerability scan results, and architectural deficiencies.

  • Providing strategic cybersecurity guidance, risk assessments, and status updates to system owners and leadership.

  • Providing weekly status reports that summarize accomplishments across assigned packages, risk posture, issues, and paths forward.

  • Creating, refining, and enforcing the operational policies, procedures, and artifacts necessary to ensure security controls are fully implemented and audit-ready.

Qualifications

Required Qualifications:

  • Certification required in accordance with DoD Manual (DoDM) 8140.03 at the Intermediate level, such as CompTIA Security+ or an equivalent certification.

  • Bachelor’s degree in information assurance, cybersecurity, or a related field, plus 3–5 years of relevant experience; or a high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.

  • At least 2 years of direct experience serving as an ISSO or cybersecurity practitioner supporting DoD systems, including:

  • Direct experience managing RMF lifecycle artifacts and end-to-end eMASS package management across multiple concurrent systems.

  • Proven experience authoring, tracking, and coordinating technical remediation to drive POA&Ms to validated completion.

  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.

  • Demonstrated ability to operate with a high degree of autonomy, self-direct work, and lead cross-functional technical teams through complex authorization lifecycles.

Desired Qualifications:

  • Ability to work effectively in a team-focused, dynamic, high-tempo operational environment.

  • Experience using STIG Viewer and automated compliance tools.

  • Prior experience participating in Change Advisory Boards (CABs).

Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

REQNUMBER: 2617151

SAIC is a premier technology integrator, solving our nation's most complex modernization and systems engineering challenges across the defense, space, federal civilian, and intelligence markets. Our robust portfolio of offerings includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and simulation; and training. We are a team of 23,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $6.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see Working at SAIC. EOE AA M/F/Vet/Disability

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.